Playbook

How to stop data leaks to ChatGPT

ChatGPT and other AI chatbots have become a routine destination for sensitive data. This is a practical playbook for preventing PII, card numbers, source code and secrets from leaving your organisation through a prompt — without banning AI and losing the productivity.

Why ChatGPT is a data-leak channel

A prompt is an outbound data transfer. When someone pastes a customer list, a contract or a block of code into ChatGPT, that content leaves your environment over ordinary HTTPS to a trusted domain — invisible to email filters, network DLP and firewalls. Depending on the provider and plan, it may be retained or used to improve the model. Unlike a misdirected email, you cannot unsend it.

What doesn't work

  • Blocking the domain. It pushes staff to personal devices and other AI tools, making the leak invisible instead of stopping it.
  • Policy documents alone. An acceptable-use policy nobody enforces does not change behaviour under deadline pressure.
  • Browser extensions. They only cover the browser — not desktop apps, IDE assistants, or the next AI tool your team adopts.

The playbook

1. Get visibility (log-only for two weeks)

Deploy endpoint detection in log-only mode first. Do not block anything yet — just measure which AI tools are used and what categories of data flow to them. This almost always surfaces more usage than expected and gives you the evidence to set proportionate policy. This is the core of AI data loss prevention.

2. Classify what actually matters

Not all data is equal. Define the categories you must protect — PII, PCI/payment data, credentials and secrets, and source code — and treat everything else as low risk so you are not drowning in false positives.

3. Set graduated block / warn / log policy

  • Block the highest-risk categories: secrets, source code, and bulk PII or payment data.
  • Warn on medium-risk content, so the employee gets an in-the-moment prompt and can decide — this both prevents leaks and educates.
  • Log everything for a full audit trail, storing metadata only rather than the raw content.

4. Cover desktop apps and IDEs, not just the browser

ChatGPT is used in the browser, in a desktop app, and through API-backed tools and IDE assistants. Inspecting content at the operating-system level covers the browser, desktop apps and IDEs alike, across major AI services like ChatGPT, Copilot and Claude — with no per-app configuration.

5. Keep detection on the device

If your DLP ships prompt content to the cloud to be scanned, you have added a second data-egress path. Detection that runs locally classifies the content on the endpoint and never transmits it, which is both safer and faster.

How Redbax does it

Redbax runs on Windows and macOS and inspects prompts and uploads at the OS level — before they reach ChatGPT or any of 40+ AI services. Detection is local, latency is under five milliseconds, and the SOC dashboard stores metadata only. See how it works.

Related: understand the behaviour behind the risk in our shadow AI guide, or register your interest to see Redbax in action.

See how Redbax stops AI data leaks.

AI endpoint DLP for ChatGPT, Copilot, Claude and 40+ AI tools. Be first to know when we launch.

Register Interest